{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:3779457c-c692-5ec6-815a-2733ce06f57f",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-websocket@9.0.90-tuxcare.5",
      "type": "library",
      "group": "org.apache.tomcat.embed",
      "name": "tomcat-embed-websocket",
      "version": "9.0.90-tuxcare.5",
      "purl": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-websocket@9.0.90-tuxcare.5"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:af99b7e4-149e-54df-b6fe-deee1a18a510",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11996 affects version 9.0.90-tuxcare.5 of org.apache.tomcat.embed:tomcat-embed-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-websocket@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b59d5029-bd77-51a6-85d7-fc0d4befd9a0",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 9.0.90-tuxcare.5 of org.apache.tomcat.embed:tomcat-embed-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-websocket@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b46ca98a-f115-5ba6-8c84-4000311b42e7",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-13943 does not affect version 9.0.90-tuxcare.5 of org.apache.tomcat.embed:tomcat-embed-websocket. Fix for CVE-202-13943 for this version has been already backported by the original developers, so brunch 9.0.90 is not vulnerable"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-websocket@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3ac7cbee-cd59-5f4c-a442-495f2711ee28",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-9484 affects version 9.0.90-tuxcare.5 of org.apache.tomcat.embed:tomcat-embed-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-websocket@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:10f1273b-66e2-5b17-a464-dfc7109fb968",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 9.0.90-tuxcare.5 of org.apache.tomcat.embed:tomcat-embed-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-websocket@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9670d44c-4b81-5c83-a60d-3bfbbfe02873",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-42340 affects version 9.0.90-tuxcare.5 of org.apache.tomcat.embed:tomcat-embed-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-websocket@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:43c69824-082b-55b9-965c-29df73a5982a",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-34305 affects version 9.0.90-tuxcare.5 of org.apache.tomcat.embed:tomcat-embed-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-websocket@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a6116b59-7476-5c98-840e-3b79663230db",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-45143 affects version 9.0.90-tuxcare.5 of org.apache.tomcat.embed:tomcat-embed-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-websocket@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d00abb01-6ac5-501d-8205-636606630fd8",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 9.0.90-tuxcare.5 of org.apache.tomcat.embed:tomcat-embed-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-websocket@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2584bc77-3a2c-58ad-bdae-14725366b449",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 9.0.90-tuxcare.5 of org.apache.tomcat.embed:tomcat-embed-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-websocket@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:02ab7001-6a17-5760-a0f0-97a2bf66eb2e",
      "id": "CVE-2024-50379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-50379 is fixed in version 9.0.90-tuxcare.5 of org.apache.tomcat.embed:tomcat-embed-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-websocket@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ee7ba82f-7c37-5804-b101-68c48b0aa093",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52316 is fixed in version 9.0.90-tuxcare.5 of org.apache.tomcat.embed:tomcat-embed-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-websocket@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0053a24a-2832-5a7e-a748-e748dc1c3ad1",
      "id": "CVE-2024-54677",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-54677 affects version 9.0.90-tuxcare.5 of org.apache.tomcat.embed:tomcat-embed-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-websocket@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d6ec1b12-36fb-523d-b7c6-f131e19f7649",
      "id": "CVE-2024-56337",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-56337 is fixed in version 9.0.90-tuxcare.5 of org.apache.tomcat.embed:tomcat-embed-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-websocket@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dd414bc3-7dd4-545b-ba7c-5795cab73ff9",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24813 is fixed in version 9.0.90-tuxcare.5 of org.apache.tomcat.embed:tomcat-embed-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-websocket@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2d001eb4-061f-5a2d-adf7-48c92a01cd6a",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31650 is fixed in version 9.0.90-tuxcare.5 of org.apache.tomcat.embed:tomcat-embed-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-websocket@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fa143423-2e63-5d27-b049-3ed63a568fe9",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-31651 affects version 9.0.90-tuxcare.5 of org.apache.tomcat.embed:tomcat-embed-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-websocket@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fdc6bc78-9a73-5da4-a301-754b5027fdc5",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46701 is fixed in version 9.0.90-tuxcare.5 of org.apache.tomcat.embed:tomcat-embed-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-websocket@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ac59f147-0971-5f54-a60a-5d6051d6d28e",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48988 is fixed in version 9.0.90-tuxcare.5 of org.apache.tomcat.embed:tomcat-embed-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-websocket@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9f117b1c-7789-5f99-b93c-f8e14deb767c",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48989 is fixed in version 9.0.90-tuxcare.5 of org.apache.tomcat.embed:tomcat-embed-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-websocket@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f4dd480e-ec0e-5169-9958-e966f3693bda",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 9.0.90-tuxcare.5 of org.apache.tomcat.embed:tomcat-embed-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-websocket@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:21e72fb8-c03d-5a0b-9fa6-0778cc563c61",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-49125 affects version 9.0.90-tuxcare.5 of org.apache.tomcat.embed:tomcat-embed-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-websocket@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c9c8692e-db96-5f2f-93e2-ff3d0713787d",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52434 is fixed in version 9.0.90-tuxcare.5 of org.apache.tomcat.embed:tomcat-embed-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-websocket@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:52fa928d-974e-5567-bbe9-6b92381ebe80",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52520 is fixed in version 9.0.90-tuxcare.5 of org.apache.tomcat.embed:tomcat-embed-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-websocket@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d7b453f0-5046-54bd-82d9-baa0838573f3",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 9.0.90-tuxcare.5 of org.apache.tomcat.embed:tomcat-embed-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-websocket@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3290adfa-781c-5479-9fe1-4fe0686c4acc",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 9.0.90-tuxcare.5 of org.apache.tomcat.embed:tomcat-embed-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-websocket@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e2b18da5-8f5e-59a4-bcb4-77c9cca6cd30",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55752 affects version 9.0.90-tuxcare.5 of org.apache.tomcat.embed:tomcat-embed-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-websocket@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aee858ac-3717-5caf-b1ac-c8fb1cbef4d4",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 9.0.90-tuxcare.5 of org.apache.tomcat.embed:tomcat-embed-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-websocket@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:754b6946-0d31-5a35-8cd3-52d100275b82",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 9.0.90-tuxcare.5 of org.apache.tomcat.embed:tomcat-embed-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-websocket@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0a5e0d61-14ff-5fd4-9b05-f1c7252a03d5",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66614 is fixed in version 9.0.90-tuxcare.5 of org.apache.tomcat.embed:tomcat-embed-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-websocket@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dc187a8c-df26-5099-a6f0-395cb627699e",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-24733 is fixed in version 9.0.90-tuxcare.5 of org.apache.tomcat.embed:tomcat-embed-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-websocket@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:46ca9e1b-ec6f-558a-90e2-75730d71415a",
      "id": "CVE-2026-24734",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24734 affects version 9.0.90-tuxcare.5 of org.apache.tomcat.embed:tomcat-embed-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-websocket@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c863e2f1-b250-532e-bb87-7555bcf7317e",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 9.0.90-tuxcare.5 of org.apache.tomcat.embed:tomcat-embed-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-websocket@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:77da68ad-ade0-51d6-bda5-2c304dff814e",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25854 is fixed in version 9.0.90-tuxcare.5 of org.apache.tomcat.embed:tomcat-embed-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-websocket@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5f7bc393-c552-5a4b-9af6-989c8449014a",
      "id": "CVE-2026-29145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29145 affects version 9.0.90-tuxcare.5 of org.apache.tomcat.embed:tomcat-embed-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-websocket@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dedeeb80-ddd9-5bc9-8128-de9c3bbdb845",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-29146 is fixed in version 9.0.90-tuxcare.5 of org.apache.tomcat.embed:tomcat-embed-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-websocket@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7f3e4500-5352-5902-bc2b-7d95533a71e9",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 9.0.90-tuxcare.5 of org.apache.tomcat.embed:tomcat-embed-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-websocket@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8146e18a-cf7c-5052-9a23-17e49f2ff69c",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34483 affects version 9.0.90-tuxcare.5 of org.apache.tomcat.embed:tomcat-embed-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-websocket@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8b2c6c6d-033b-58f2-8cc6-5e7167c7d177",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34487 affects version 9.0.90-tuxcare.5 of org.apache.tomcat.embed:tomcat-embed-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-websocket@9.0.90-tuxcare.5"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-websocket@9.0.90-tuxcare.5"
    }
  ]
}